← Back to list

PE Studio aplicado a alguns executáveis

EXECUTÁVEL: OblivionLauncher.exe

Helton Hernandez hxh · 2023-12-07 00:10 · 0 claps · 4.6 min read
#information-security #pestudio
Open on Medium ↗

PE Studio aplicado a alguns executáveis

EXECUTÁVEL: OblivionLauncher.exe

Procedência executável: Torrent

SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Thu Apr 06 15:25:44 2006 | UTC -footprint (sha256):2AB982D924FBBF4B704F95E001842DC83BF95DEE56CEF26141531E4DB758159E -signature : Microsoft Visual C++ 7.0 MFC -cpu : 32-bit

SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total: Bkav; W32.AIDetectMalware

-o que aponta no MITRE ATT&CK :

Execution TA0002 Defense Evasion TA0005 Discovery TA0007

SEÇÃO STRINGS: -total de strings: 15035

SEÇÃO IMPORTS: -os 3 primeiros importas com flags, e seu grupo (coluna grupo)

WritePrivateProfileStringA — grupo registry

GetCurrentProcessId — grupo reconnaissance

GlobalMemoryStatus — grupo memory

==============================================

EXECUTÁVEL: gta_sa.exe

Procedencia executável: torrent

SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Thu Apr 28 15:31:22 2005 | UTC -footprint: A559AA772FD136379155EFA71F00C47AAD34BBFEAE6196B0FE1047D0645CBD26 -signature: Microsoft Visual C++ 7.0 MFC -cpu : 32-bit

SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total:

Bkav / W32.AIDetectMalware

-o que aponta no MITRE ATT&CK :

Execution TA0002 Persistence TA0003 Privilege Escalation TA0004 Defense Evasion TA0005 Credential Access TA0006 Discovery TA0007 Collection TA0009 Command and Control TA0011

SEÇÃO STRINGS: -total de strings: 213.732

SEÇÃO IMPORTS: -os 3 primeiros importas com flags, e seu grupo (coluna grupo)

GetOverlappedResult — grupo synchronization

RegCreateKeyExA — grupo registry

RegSetValueExA — grupo registry

==============================================

EXECUTÁVEL: PlayGTAV.exe

Procedencia executável: torrent

SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Sun Mar 22 12:24:23 2020 | UTC -footprint: 9D4D78F8249CC4F45026F6C545499C6F5AA6DB87852798B82EF2FC788D310290 -signature : N/A -cpu: 64-bit

SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total:

APEX — Malicious

Cynet — Malicious

TrendMicro-HouseCall — TROJ_GEN.R002V01K323

SEÇÃO STRINGS: -total de strings: 7870

SEÇÃO IMPORTS:

WriteFile — group file

CreateProcessA — group — execution,T1106 | Execution through API

RtlLookupFunctionEntry — group execution

==============================================

EXECUTÁVEL: devcpp.exe

Procedencia executável: site oficial

SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Fri Jun 19 22:22:17 1992 | UTC -footprint: 5E490F306CACE14810C9FDABF7E30A2C2E1941BEDD5E00C54B24E208926527E1 -signature — exemplo : N/A -cpu: 32-bit

SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total: N/A

-o que aponta no MITRE ATT&CK: N/A

SEÇÃO STRINGS: -total de strings: 54336

SEÇÃO IMPORTS:

==============================================

EXECUTÁVEL: Wireshark.exe

Procedencia executável:site original

SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Wed Aug 23 19:07:58 2023 | UTC -footprint: 85947539A421A8A4C547A09E4351799BBC73B89E175DDBA4CE6A0936BB07AF2E -signature — exemplo : Microsoft Visual C++ -cpu : 64-bit

SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total : N / A -o que aponta no MITRE ATT&CK: N/A

SEÇÃO STRINGS: -total de strings: N/A

SEÇÃO IMPORTS: N / A

==============================================

EXECUTÁVEL: aom.exe

Procedencia executável: cd rom

SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Fri Apr 23 19:56:51 2004 | UTC -footprint: 34D66DCBBD9EB8174083E4C44C6FCC26F1E369653ABD446513727A0D86DFF29F -signature — exemplo : Microsoft Visual C++ v6.0 -cpu : 32-bit

SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total:

-o que aponta no MITRE ATT&CK:

SEÇÃO STRINGS: -total de strings: N / A

SEÇÃO IMPORTS: N / A

==============================================

EXECUTÁVEL: DB Browser for SQLite.exe

Procedencia executável: site original

SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Thu Oct 10 13:12:07 2019 | UTC -footprint: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 -signature — exemplo : n /a -cpu: 64-bit

SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total: n /a

SEÇÃO STRINGS: -total de strings: n / a

SEÇÃO IMPORTS: n / a

==============================================

EXECUTÁVEL: uTorrent.exe

Procedencia executável: site oficial

SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Tue Nov 21 03:20:03 2023 | UTC -footprint: 4089DAC808A6A0E8C4007185D64844503DED6606B6F063D769F65A9402ED57F5 -signature : UPX -> www.upx.sourceforge.net -cpu : 32-bit

SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total:

-o que aponta no MITRE ATT&CK:

SEÇÃO STRINGS: -total de strings: n/a

SEÇÃO IMPORTS: n/a

==============================================

EXECUTÁVEL: firefox.exe (tor browser )

Procedencia executável: site original

SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: n/a -footprint: 53C54C98971CD0E1121FDFA4691E7EAA392A4EED09710EE15B269F7E22470C4E -signature: -cpu : 32-bit

SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total:

SEÇÃO STRINGS: -total de strings: 26373

SEÇÃO IMPORTS:

==============================================

EXECUTÁVEL: ProtonVPN.exe

Procedencia executável: site original

SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Mon Apr 17 09:13:48 2023 | UTC -footprint: 558E395C8D560BA2257836542CF54E1D491F35BBD90F1C710DD626AB94ED99B1 -signature: Microsoft .NET -cpu : 32-bit

SEÇÃO VIRUSTOTAL:

SEÇÃO STRINGS: -total de strings: n/a

SEÇÃO IMPORTS: n/a

==============================================

EXECUTÁVEL: VirtualBox.exe

Procedencia executável: site oficial

SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Wed Jan 11 16:40:35 2023 | UTC -footprint: 0E7C8FD7EA6E25989E611FFA93CD7671B830643A60481659A4B37741614FE536 -signature: n/a -cpu: 64-bit

SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total:

n/a

SEÇÃO STRINGS: -total de strings: n/a

SEÇÃO IMPORTS: n/a

==============================================

EXECUTÁVEL: Scratch Desktop

Procedencia executável: site original

SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Mon Aug 05 17:24:45 2019 | UTC -footprint: 6200BB3C9B06DF65A27655F8A28A9143E5394F62FE12E893C9AA16785BCB6C97 -signature — exemplo : Microsoft Visual C++ -cpu: 32-bit

SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total: n/a

SEÇÃO STRINGS: -total de strings: n/a

SEÇÃO IMPORTS: n/a

============================================== EXECUTÁVEL: 1001.exe (cd rom com 100 jogos)

Procedencia executável: CD de revista

SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Wed May 14 16:53:28 1997 | UTC -footprint: 2E76C2B1DAA4706F87D81AAB426B4647919F9BAD410626D81E741BE082F46BDD -signature — exemplo : Microsoft Visual C 2.0 -cpu — 32 bits

SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total: n/a

SEÇÃO STRINGS: -total de strings: 49410

SEÇÃO IMPORTS:

==============================================

EXECUTÁVEL: Google Update Setup.exe

Procedencia executável: site original

SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Wed Jan 10 02:10:49 2024 | UTC -footprint: 730A65C0941A611DA25B0782AC159870023D324C304C4DA52870D89A683882CB -signature: Microsoft Visual C++ -cpu: 32 bits

SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total: n/a

SEÇÃO STRINGS: -total de strings: 41028

SEÇÃO IMPORTS: -os 3 primeiros importas com flags, e seu grupo (coluna grupo)


메타데이터
post_id
03f38303c71b
slug
pe-studio-aplicado-a-alguns-executáveis-03f38303c71b
url
https://medium.com/@heltonxh9/pe-studio-aplicado-a-alguns-execut%C3%A1veis-03f38303c71b
canonical_url
https://medium.com/@heltonxh9/pe-studio-aplicado-a-alguns-execut%C3%A1veis-03f38303c71b
author_url
https://medium.com/@heltonxh9
status
ok
fetched_at
2026-07-26 18:12:23